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U m^BCgjft^o Z*lfC<fcy, Bfi, m<b, gift 
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[»#JS1] h9-^$aCT. /<X9- 

K***-rS^a*#H-e. ft£<©»[=l|-f SDiffie-H 
el ImanM^S^^ffl^Tft^^ g x y £±j£-f SJM 

y. ii&Ksr±s3i*fcj:t;sa£3i*£*u 
«ti=wrs»3i**sff-rs-t[=«fey/<7>-5'm 

7- h*<ofrEii«t[=WLT»af3i**Sff lt g x £ 
«i? fc s = t &m 1 1 *a „ 

I E«03*;i„ 

[§!#il3] fJE-*S*#^\ fiEfl&73ii*#frb 
g y £S«U fuK£;ffl^g xy £±j£^-l>X^? 

[W*il4] fJE-*S*#^\ fiE-* 

s*#rotisij^ S5Efl&*s*#roiSSiJ^s m, g \ 

HrE****. te*t«nE/<X9- h*0>5*>0>'>&< £ 

I I ■o<Dm&tttm-&^tiz&-DX> b5ea&*s*# 

* BEf SXf^^JbCttliCi t -T SB 
SlJ^s B5Efl&*S*#(OiSSlJ^s rru g", fJEft^U 

SBEf 6< nit IX fcS c t £ft mt + -SB** 3 IE 

SiJ^ B5Efl&*S*#(OiSSiJ^s m, g\ aiJE**8f 
®. ts&tffflsZ/ixrj- Kro 1 -o<DM 

5ci t *B *S 3 K«<©*». 

[§!#il7] g "i, itiiB/U 1 ?- K03S 

mt i=» L-csssassnr-r s - 1 1=* y mrKfl&ss* 

5Xf7?i, 

fiEHft ^ i=w Lxm^n^mn lt g '^ttm-rs 

X^-v^i:, 

frE-*a*#A<. lHME**iMBg x, £W-*-fSX : 7 L 

•^i* * sn#« 1 E«ro 



frEfl&sa**©^^^. m, ^ frE**w 
fcit/fflE^x'}- Kro kbi -d<dm 

Wit LT*yi'3>8£±jrf SXx l-*Tf 
■Set £ ftttt-f SB *« 7 K«<0*ft. 

r**»!E g x y £±j£-f -siiii ^ai-fc^-t, 
gi*Ma»#i-l«*aa)»±m7ct?fey , 
[=H»<©ffiS-e& y . y r±fl&*a*#[=i«a(offi«-cfc 

y, ll&KSr±S3i*fc<fct;Si£3i*£*U 

-r 7 roBiSti: i=*rr ssssassnr-r s - <t i=* y 

^-^m^gL, m»*a»fi:Sfit*Xf«;? 
£*TL, CHl-=fc L J. fl&73^*#l*. mi, 

;^^stTLTg x ^tt!iiL, mm^mme 
* w ittmtz>zktf-n]mx&z>zkitftmktz> mm 

Hf*iI10] B5E-73S*#l*^7'TT>h-efc 
bg'^SIfL, fJEft^l5^g xy £±)S-r-i)X^-v 

g y . HK£*8«. fccfct/flE/^X^-K^y^r^ 
7 , roa*.(0 / >'EC< 1 orolliliriblx-r-Szirlcd;^ 
T , flElte* a»#£|g|jE-r S X x ^£ £ b 5 

Hf*in 3] ttjE-73S*#icaj*po5'r>f : "-v'7x 

ICtLt, «IJE-*a»#A^ g c £tt^1-i>X^-v 

f[E-*a*#A<. 'M<ttg c i, HK-*S*# 
03lISlJ^s f!Eflil73S*#03lISlJ^s m, g y , ftJEft 
fccfct/flE/^X^- K^'J 77^f 7(D o *><D'P 

BIJE/^X^-K'OJ V7^(7(DmWin^.t: v ilt, 89 
E-*S»#A<, S = C-e viLT/<7>- 5*s£it 
ItSXf7?i, 

fJE-*a*#A<. SfcJ;t;g c £tuEflil75S*#^^ 
If-r-SX^-v^i:^ $ blc^L, CHI-J:y s SUEffi* 
fuKSfcJ;t/g c roffil::'>&< 

So* WE-* S *# *BEf S - 1 A< RJttT & ft w 

[ifsfcin 4] tiJE-73S»#A<, taE-73^»#ro 

ISSU^. HKfl&SS**©^!]*. m, g y , fiJE*^ 
8«, g c fiJ:t;illB'U9 - K'OJ 77^7roa%03 



2 



[B#«1 5] frE-*a*#*«, flrE-*a*#0> 

[c£«-T4X^:/:?£S&[c*U Z*UcJ;y, ffJEtife 

[B*JS1 6] SJE/^X9-KH'J7r^7*^BH« 
<bU frE/<X9-K^'J7r>r7a))lt»W«*Wfflft 

vjuHt-^ics-^-c, «rE-*a*#f*frEtt*a»# 
^KEi-sct^at-r sb*«i ie«o>*3So 

7] gnE-*a*##, mrE-*a*#a> 
m®]*. m^fe-fi^mmomm+s m s g \ sue** 

Wffi* fJE^>#Affi s fc<fct/iHE/*X9 — KKij 77 
*3S1 6E*©*fto 

- K***-TS-a*#IH-e, W^ro»rcB|-r-&Diff ie 
-He I lmanl!fe£&£ffl l*T#*«« g x y ft. 

x r*ffii*a*#icHaa)ffi»-eft y , flrE#r*a¥£*£ 
wm&t [znt L-csa***ff-r « - tie* y we* 

*a*##tt»Lfc/<7>-*m£, flrE-*S*#A< 
SIE— *a*#j£><. m<h s ttiWE/<X9— K(D 

se>ic % frE**Wffig xy *tt*-rsx^^^** 

[B#JS1 9] fJE-*S*#fifrE/^X9- K^E 

-rsB#«i sekdas. 
X9- KrosjEBiss^^-rffi^Effi-rsA^ HE-*a 

*#[±fTE/<X9- K*EttL3S^zt*1*«frSB 

*ai 8E«<z>*a<, 

[B*«2 1] frE-*a*#f*-9— /<-e*y. me 

111 8E«<7)*&o 

[B#«2 2] fNE-*a*#tf. flrE-*a*#0> 
UlSiJ^s ilEflfc^a^flBi®]^ rru g \ fjE** 

bis*. «E«*a»#rcafflf «XT^^t*6rc* 



[B*S2 3] flrE-*a*#A<* S«ffi£. f»E- 

*a*#<z>tss®j^ fjfB^a*#(Di^ij^> m, 
g\ fJE**Wffi, fc<fcr;frE/<x9-Ka)a*a)^ 

a^^BBE-rsx^^^s&ic^-rszt^ftt 
■rsB*ai 8E*o)*fto 
[B#S2 4] fjE-*a»#A^ fiE-*a»#<z> 
r®]^ frEft&saMfloMSij*, m, g \ we** 

*3<fctffllrE/<X9- K(7) drt 1 0(0 

BIS*: Lr-b^i/3>«*±«-r4X^^^**6(c* 
1-«ci*W«fr4B*ai 8E«0)*fto 
[B*S2 5] «E-*S*#^ g y t, ^&<t 

surf sx^^wu ziiic^y, fiE**a»# 
r*, ut. *&<ttfrE/<x9-Ka)frEii»tic« 

LTll^>t^^jltTLTg y ^tttiiL s £bfc, WE* 

*«« g x y s - £ # wift-e fe s c: fc £ 
-TSB3RJS1 8E«a>*& 0 

[B*«2 e] h^-^*ai:T, -a* 

#Pb1T% 1*Sa)i¥[cB|-rSDiff ie-Hel lmanl[ii£l&£ffl 
l^T**r«ffl g x y £±J&t Silffi *&[ci3ivc\ 

gf*i^a»#[cHfiia)8±fiE7c-e&y, y f*-*a»# 
icK»0ffi»-efcy. 

x f*ft&*a»#[cittfii<Dffi»-e fe y , siE8f*»3S*fe 

yfrE«i*a*#^ti-*Lfc/<7>-*m*, me-* 

a^^ftfi-rix^^^t, 

frE-*a*#*<, m<t s ^3S< (btfjE/^x^— 

'J 7 y 4 70)frEII«fclc» LTSita** Sff LT g 
x ^tttHL, fJE**^g xy ^ff^1-^)X 

[B*S2 7] siE-*a»#fi-ti— /N*r*fcy, he 
ffi*a*#f±^7>r 7>h-e*«zttit*t-r«B* 

II 2 6E*0)*tto 

[B*S2 8] SlE-*a*#A^ SlE-*a*#0) 

ttra^s fjE^a*#(Di^ij^, m, g \ fjE** 

fc c fct;fJE/^X r 7-K^ l J7T^7(7)5^0^^ 

<<bt ioo>Bi*t* «E«*a*#rca«-r«XT^ 
^**e>rc*-rszt*i*ftfrsB*a2 est©* 

o 

S = C-evT'fey, 
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fTEffi* a * BK-r * X ■? v ^ t * 6 1=*+ 4 c 

WSJ*. fltEflil^S*#03lISlj^, rru g \ fite** 
g c fc=fctffJtE/ , U r 7- K^'J 77^7(05^© 
'>&< it 1 oroSUSt L-t-tz-v va >«£±Jifc-f SX 

Hf*il3 1 ] fltE-^S*#^\ 8iME/*X9- h** 
'J ?7"f 7£^Pjfltl<!: L, fItE/^X9- ^'.177^7 

^^ffl^r^i/yAfil^Bt^b-rsxx-y^t. 

f-;^**?)ttt4^t^iit4B#S2 6tE 

Hf*il3 2] fItE-^S*#^\ fItE-^S*#03 
IISiJ^s fu!E^S*#rotISiJ^ m s g", 8IJIB** 
fltE^V^Affl, fccfct/fJlE/^X^- K^'J 7r 
-f7©5*>0>'>&< k± 1 o<0||«t LTlKMEfl&SS* 
#icj;yit^$tLfc®ffifit[cs^^-CB5iEfl&*a*#^ 
BEf 4 X ^ -v ^ * $ b l= *f 4 z t £ 4$ ft 1 1" S If # 
II 2 6!E«ro£;£„ 

IISlJ^s fltEflil^S*#03lISlJ^, rru g", fJlEft^f 
SS^s BUfE^V^Afis fccfctffjtE/^X 1 ?- K^'J 77 
-< 7(0 5 *.£>'>&:< <tt 1 oroSUSt Lt-tr-r>a>i 

*«2 6IE«£>£;£„ 

[ftflOttll&Kfl] 
[0 0 0 1 ] 

[fESB©«-f 4 *SB SH tt. * y h 9— 7 SEE 
fcffiS*-:/ h 9 -4/BBEiSJ: ha;H=B+ 
[0 0 0 2] 

Kft»»-C*fto BEfi-Jttfc, «a>a*0)1-3*fctt 

■ □.-ififto -rat)*, ffi«o)cfc5ft±ftw-a«ao 

i^iWfIA5*A« (ATM) [4, ZHb(?)9 
*,(5)20 s -ffcfr^u -tWftoTI^SiO) (ATM 

(BtES-^s PIN)) t^fitSf So ATMEIIfi, 



7<t^&*+L % ATM*- K<0#££fitKLjELlv|i$R 

[0003] mm^u^x. m&mts f-***; 

ajPelics^^ti&ttiifi&b&^o zftfi-JiSf::, £5 
<f 7>hitf- /W, BElc«<MO>Mlcffli%«fcft 

[0 0 0 4] f-**^ h9-£, ftfc, y 

hcz) £ a * ^ h 9-^7 £ a i:r o>BlEf4H 

So tta.fi, ftSS (eavesdropping) £ 
h £U— /^PelCOJlffi^S-rS Z tied; y , 

t/U^- K) ^^-/^[cfltt-r^f^^LA^b^feSo 
t5 1 oa)^^^©aSfi % x^-7^r>^*-r?fe 
So z^f^ s Aicjsyrs-rctrccty, 

©<fc3&*»"ei** ^^^TVhfis ^;±M(sensitiv 
[0 0 0 5] ^b(c s /U9- K(cSr5<BliE^ , P h=i 

-Tfttir&^oiKaifa^wLr, y taft/u 
l s ±Eo>afi!ra)3*a)i oic^yjaj^A^Lfctflo-e 
[0 0 0 6] h9-^BE(cfi**#*3Saffi36<ftl 

1 a>»«rcr* % *7-f7>h*>xfA±i:*fi«Etf 

[0 0 0 7] «10)»filcBiLr, 7lc^ffi1fi^-^(c 
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Its ftLTa^lTttftfeSl^WfflCsecret)^-* (flla. 
Its Btt*-/<£****i«W*«) SK£I»±L 
*&ffl^fi&l^gSi*a)(sensitiv 
e)^-£ ffiBE-y— /^<D^BB») i^SftSo 

&Sfr b ^ s (c fi , iiip ^ * zl 'j t- -< fttttfj&s-e fe 

60 ^b(c s /<x 9- Kfc<fctf*ttttE1I ^r-^aW* 
ir^&So Z0)JB1 fl)^7XO?P h^W0t5 1 o 
[0 0 0 8] *2©#Wd\ ^5^f7>Hci3ltft*l* 

/ *X 9 — K £flH^T & * * aJJ ^ -f £ tfKE £ffi 

9*KEfc£t/»£ifta>?P h=ul^l>< 
tSo Z;ftb£>^P h=UUf£, D. Jablon, "Strong Pas 
sword-Only Authenticated Key Exchange", ACM Comput 
er Communication Review, ACM SIGCOMM, 26 (5) : 5-20, 
1996, [cEKSliTI^So -^b(7)/U9-KW[:J; 

■ E K E (Encrypted Key Exchange) (S. M. Bel I ov in a 
nd M. Merritt, "Encrypted Key Exchange: Password-B 
ased Protocols Secure Against Dictionary Attacks", 

Proceedings of the IEEE Symposium on Research in 
Security and Privacy, pp. 72-84 s (cEtJt) 

■ A - E K E (Augmented-EKE) (S. M. Bel I ov in and M. 
Merritt, "AugmentedEncrypted Key Exchange: A Pass 

word-Based Protocol Secure Against Dictionary Atta 
cks and Pasword File Compromise", Proceedings of t 
he First Annual Conference on Computer and Communi 
cations Security, 1993, pp. 244-250, icEtJ) 

■ M- E K E (Modified EKE) (M. Steiner, G. Tsudik, 
and M. Waidner, "Refinement and Extension of Encr 

ypted Key Exchange", ACM Operating SystemRev i ew, 2 
9:22-30, 1995. (cE«) 

■ S P E K E (Simple Password EKE) fccfct/D H - E K 
E (Diff ie-Hel Iman EKE) (ivfjii, D. Jablon, "Stro 
ng Password-Only Authenticated Key Exchange", ACM 
Computer Communication Review, ACM SIGCOMM, 26(5): 
5-20, 1996, (CE«) 

■ S RP (Secure Remote Password Protocol) (T. Wu, 
"The Secure Remote Password Protocol", Proceeding 



s of the 1998 Internet Society Network andDistribu 
ted System Security Symposium, pp. 97-111, 1998, [c 
KM) 

■ O K E (Open Key Exchange) (Stefan Lucks, "Open K 
ey Exchange: How toDefeat Dictionary Attacks Witho 
ut Encrypting Public Keys", Security Protocol Work 
shop, Ecole Norma I e Super ieure, April 7-9, 1997, 

ICE«) 
[0 0 0 9] 

%±v&&zttfmM2ixri^^ztv&& 0 hps, 

S. Patel, "Number Theoretic Attacks on Secure Pass 
word Schemes", Proceedings of the IEEE Symposium o 
n Research in Security and Privacy, pp. 236-247, 19 
97, lcE«**iTL>SJ:9rc E KE^P h=UUf£, 

^■b + i'J^-f 0)MStt<7)tl^A>b, Z<t# 

[0 0 10] ^i^ttiIS0 9/3 5 3, 4 6 8^ 
(USB : 1 9 9 9^7^130) fCf*, ^BBftBf-^* 

-*BH?p hPJU^EK**iT^So z<7)^p h=UU 

<hj&<EE**iTl>So 
[0 0 1 1 ] 

^ h9— {/SE^p h=ui/*Stt-r4o *^<D^p K 
=iJHcJ:*itf, -a»#s6<, Diffie-HellmanfiO)«3tlft 

3lc % Diffie-Hellmana0)*3tlftrcj:*ifi, 1*S0)lvb 

Wfflg^^ifiE-rSztA^tS^^lc-rSo Diff ie 
-HellmanfiftSft^P h^^SiLTW^ 
p hPJUfiSEO)tl^^L&^o 
[0 0 12] *«^(cj:iifi\ Diffie-HellmanI!<Z)**r 

U^ElIt 6 Z # « d; a (cfcl * ftfc ^p h p ;u 

E#f;J\ Z(7)^p h^JI/^tfcS^t^EBLfco 
*^0^(Ccfctlfi, -^*#^Diffie-Hellmanffig x £ 

z;h£, ivbfl>fti*»»*m^C{l>&< 
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«f S £ o s SSI* is £ t/SifcH* £D i f f i e-He 1 1 man 

jft-Cfcfto ±^<D£ol^s Diffie-Hellmanfflg x ^ s '> 
T. g x f*. /<X9-K0)^a)BI«tfi^**LSZtt 

=i;nc»-rfta»#a)«iaij^ta)HBtt»***iftzi: 
[0013] ^%BM<D-mtm[z^ti\f. a*#ra\ '> 
a^w^*f[:atL, a«s*ifcffi£#a*## 

1 oroa^R®]^ Diffie 
-Hellmanffi (g x Sfcfig y ) % fc<fctf** 

a)'>4<ttioa)Bi»*W-*-rszticj:y % 

[cJ;oT s BMRMlcSl^BBE-f So l^?Mlfra>a*# 
jMELIV^X 1 ? — K£Bf* LTl^ftl^Jf 

a*#j£><s »3S**ffll^riBa)Diffie-Hel lmanffi£'> 
^£i/<X9-K<Z>BIS£fi£U fiStLTttfett 

35*£ffl^T*6*a»#0)Diff i e-He I Imanffl^tttH U 

[0015] ini^p h=uurc»-rft-a»#f4, \zt 
Aj£<Dm^. ^^^7> h=i>tfi— /<3>tf 

Hffiffl r* r± . / fcit & -t * zl 'j -r ft lb [c » 



T\ ft^yrc, l^f*4/<X9-K><U?T^7*^iL 

b^s Effi-fSo K^'J ?r-f 

^p h=uK3\ /U9- K^'J 7r^7A^-»[cHlBa) 
/U9- KC0^^ l 'J[^ffl^b^^^c<^:^|^L^T^4, ±E 
0)lll6fiiJtfiftlLTL>So LfrU -9— /WH(Ra)/*X 
9- K^b^l^:46, flfe*a*#A^HIB[ciELLV^X 
9- K^'J^r^TSfcfiSBSflO/^X^- K*Bf*LT 

[0 0 16] 

[0 0 17] n&jEfCfi, *^Sfrb*^ Tetania f ic 
OL>T s SlcM-f S-f^<T<7)x[CJsfLrf4f (x) ttit 

fd\ f (x) = y «!:fc§£5fcS<Z)^y£Molt§<0a< 

W-««(cSff^ffi-eftS*^, f f*-*iRittBl»-efc 
p^L«a, g ^ p^at-rsmas ere 

t^^s 1 p - 1 (DffiBIOS) (7)^iS7t<b1-^o 

CC0Jf^ s f (x) =g x mod p fi-^f^s —~h 

lRlttBi«-e*St<5S**iSo *a)itll* (IMftttftH 
[0018] kfccfct; i *-b*i'jT-r/<5>— 

{0, 11 *R-Jl*Ma)«*tL, {0, 1} 

n £s **nO)^Jl*Ma)««i:-rSo SftfitBiftc 

(n) \ts ftM<D c>0[C'^L^T, -f^T(7) n > n c [C 
*fLT£ (n) <1/n o fcSft<feaSn o > 036<** 

X\<D fcSffi r (CjsfLT p= r q + 1 A<q i: 

[0 0 19] Diffie-Hellman»3E*i:P*fi*iS»3E*l^ 
Ph^Jl (W. Diffie and M. He 1 1 man, "New Direction 
s in Cryptography", IEEE Transactions on Informati 



6 



on Theory, vol.22, no. 6, 644-654, 1 976. icER) 

b7>?A[:xJI^ fcf£U Z q = {0, 

1 q-1} (&S^f**[C % q^SttSS 

ft) "C&So X^^1 0 4t\ Af*. X = g x mo 
d p&tiWt&o X^yZ/l 06t% Af£ s X^Ba 
iSfi-fSo X^y^l 08t\ Bf£ s Z q ^b7>^ 
lCy£JLR 0 Bli, Xf 7^1 1 0t\ Y = g y mo 
d p£ft*U X^y^l 1 2T% Y^A^sjSfi-f 

s Q ^<Dm&t\ **wfflg xy cr&t)*, mi 
^\ AtBo>H#rc<feytntwiiBfc&«. (ftfc\ n 

Ts mod pT*#*T^§C£#SI3bfrT*&§«^lC 
lis Ea*»*lC-rSfcft, mod p(7)fE«^*H§-r 
SZttffcSo ) X = g x ^X^y^1 06tA^bB 

^mmztitctcSbs 7.=^v-f^ 1 6T% Bfd\ x y £f+ 
JW4z£[::J;y % ^^^g xy ^f-r^1-^)Z<h^ 
#£o HlfiMc, Y = g y ^X^y^1 1 2tB^bAA 

So -3LT S **r»ffiS[i, S^ftillfCDfc^CDiz^ 
y3>i<bLt, AirBlcJ^iJffl^biiScirA^Rrffii: 

ft£o 

[0 0 2 0] Diffie-HellmanftSSMi. fe^flCOfflRffi 

-etSffRrtB-efcSo »f*a*#icjaa-efty, i. n. 

Herstein, "Topics in Algebra", 2nd edition, John W 
iley and Sons, New York, 1 975. lz\£#i(D<£ o dER 

1. a, beGftbl£\ a ■ b^G (EBISTL^S) 0 

2 . a , b , ceG^bll a ■ ( b ■ c ) = ( a ■ 
b) ■ c (fgft*) 

3. t^TOaeGC^LT, a ■ e = e ■ a = a t ft 

4. ftm<7)a eGC^Lts a ■ a" 1 = a" 1 ■ a = 

e ^ft^cfc^ftTta" 1 ^^^ (GlCfc 1+43^0) 

[0 0 2 1 ] LTs cty-jHWlc, Diff ie-Hel Iman 

xfccfct/yf*. »a)7cO)ft*-C*fto *ZT\ g^G£ 
S¥£j£te<!:"3~£>I¥g = {g, g ■ g, g ■ g ■ g, g ■ 

g ■ g ■ g, ...} £#tl£o ■ 

So 9\t LTs G0)»3i*A<S*-e*S»^. G= {g 

\ g 2 . g 3 . g\ ...} G0gsi^D 

G= 11 g, 2 g, 3 g, 4g, ...) 



&g x (*s »±fiE7cglcWLT»3S**x[lffffl*i*S 
y f*. x ■ y" 1 <!:LtSt$tLl)o 

[0022] «0^n HffiffliCcfcSffissiiEis^t; 
Tvzf\tm2%m%Biz&*DTmfi2tiz>» ai* 

^^7> hTvV^ftU, Bfi-9— /\ f 7^»tft5o 
9fc % *^(£> Afccfct/Btf^^V hfccfctf+f— 

#Afej:r;B[cjifflRrffi-e&So £ep[* s a*#inia>a 
[0023] -?u h=uu^BB*&-rsfric, ^^r>h 

§/U9- K^^FJf^-f Stfi^-f So 
[0 0 2 4] ftfc\ JiTFO^P h=UH3\ U— Aftcfctf 
^7>T7>h(DM**BIE-r4o LfctfoT, Aft 

SRTffittA^fcSo ^^7>hf* s i»i#^SBELT 
£ b oT+J— AdT^ izX Lcfc 9 <b-r SiSTfeS pTMi 
^feSo ^— ^l^f#fdftl^^^r> hA^bS 

asita^^j: 5 1 Lraijo)JiE&-«— /ta>^y * 
[0025] a«#rcri*»rcw636xrc&«j:5rc, » 

- KflOMlBT'elift-f ft^P^5A**ifc3 >t°zL-^ 
tLTSgRTtt-eiSo =i>t°zL-^^py^A=i- K 
lis 3>tfi-4rRTttaft (ftilff, >^E'J) icEft* 

=i- Kfi N =i>tfi— drflo^p^^-y-rcctysff* 
Wo *«W(Z)Wffl»a)Eit(c»-5^r, s*#r*fcii 

ss^tifc, ^p^7A^tLfc=i>tfa.-^fiaii#[c 

[0 0 2 6] g]2[cM l Js Xf'V?202t\ 1 5 ^ 7 
[C s Xf'^2 0 4t\ ^^^7>hfi, m= g x ■ 
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(H 1 (A, B , 7T ) ) mod p t LT S 

Rsj^-e&y, Bfi-ti— /^-swmsij^^&y, * 
K-e&y. h , f i ^ > y a / \ ^ v zl n ^ -r? fe u % ■ \tm 

3S*£^-f 0 H 1 (A, B, 7T) f£ s |£X*<G (p 

^^yA/N^^iBIStiVfiiiSo H 1 fi N z 

feftl^fc*. | p |+sectf^h (tctcLs I p I fi 
pCDtfy hBfCfcy s s e cttiz^n. 'J^-f ^ 

I*. 1 6 0t-Tftzt36<Rrj|B-C*«o -fticz 

■ SHA-1 (FIPS 180-1, "Secure Hash Standard", 
Federal InformationProcessing Standards Publicatio 
n 180-1, 1995. (c|E«) 

■RIPEMD-160 (H. Dobbertin, A. Bosselaer 
s, B. Preneel, "RIPEMD-160: a strengthened version 

of RIPEMD", Fast Software Encryption, 3rd Intl. Wo 
rkshop, 71-82, 1996. dKB) 

[0 0 2 7]^7^7>h - +f-/mz:tlZ-mtf}-V 

« (*^U) (A, B, 7T) £ffll*So ^MftiZ^'J 

MEEdi*, hfej:r;-9— /<a)*HiJA<i»s-e 

Hf*\ 4>&< £ K(7)Blfti:, Diff ie-Hel Iman 

fflg x ticWLr»3i**Sff-rsztrcj:y % 

<i:t/U9- K©IHS*Diff ie-Hel Imanffi g x <t££^-f 

Diff ie-Hel Imanfflg x ^/^>—^m^btttHpJf^"rrfe 

fcSo Z^DDiffie-Hellman^ig x (^tttH[coL^T^is X 
x^^2 1 4rcHLTJSlT-CB«lcBlwrSo X^y? 

2 06t\ TV M*. /^7>-$m^- /W£ 

111 "3" & o 

[0 0 2 8] /<5>-*m*S6«-rft£. Xf 4 V?20 
8Tj\ "9— /*fd\ /<7>-JPOmod p-eftl^Z 

ffi#o mod p-e&sa^, "9— /*fi^P h=WU£ 

«7-rSo oriz p *rc«a?&^6-e*«. -£>ffitf 

0 mod p-e&l^if £\ Xn-V?2 1 0 Tj\ U— /< 
Its Z q ^bffi»y<!:Lt7^A6:il$M„ Xf'V 
?2 12t\ U— /^l£, £ ju fcDiff ie-Hel Iman 

ffig y £ttA-f£ 0 X^V?2 1 4-C\ "9" — 



ff ie-Hel I man^^^g xy (Z<Z)7p h=UI/TM*o-C 

(7= (m/ (H 1 (A, B, 7T) ) r ) y mod p 
mz s Z(7)X^^^(COL>T N SblCfifffllcBlE-f § 
(Ea*«*lct5fcftmo d p<Z>K«£«m&f 

3t> x/ytfx ■ y- 1 a^|^J; 

9Cs Xf7^2 14[:JSlt§m/ (H 1 (A, B, 

7r) ) r mm\z. mt, '>&<tt/<x9-Ka)ii* 

bC0mC0ffl^^A-r^<t, g x - (H 1 (A, B, 

7T) ) V (H 1 (A, B, 7T) ) r = g x £t#£ 0 L 

£if^s afiLfc/ 1 ?^^— 5rm(7)ffiA^bDiff ie-Hel Iman 
fflg x ^tttH-r^c<t^'rr#^, 0 oLt, Xf^?2 

1 4[cfcMtSft»0)IISa, Diff ie-Hel Iman* 
^$^g xy £±J^<i> 0 

[0 0 2 9] ;^[C S Xf ^^2 1 6X\ 'Mts k = 
H 2a (A, B, m, /i, (7, 7T) £ft3t-f£ 0 fcf£ 
L s H 2a fd\ sectfyh (fcf£L s e cfi-iz^ri U 

7>yA/\*v^iBIS»r*&So /^>-£kf£ % JUT - ? 
BUfi-f §£51::, *-/WELlvU9- K*Bf*LT 
L^Szt*BliE-r5fcAlc % ^7^f7>hArc*y«ffl 

> - ^ cfc t; k * ^ =? 4 t > h &m t a 0 

[0 0 3 0] /^y-^jU&cfctfk^lf-f ££ s 
^T>hfi, Xf^7°2 2 0t\ cr = ju x mod p 

^ = g y -Trfe^fr^ s ju x =g xy f*Diff 
ie-Hel lman*^Wffl-efcSo Xf ^?2 2 2t% ^7^^ 
T>hfi, ia<7)7r<7)£ntt!£ffl^TH 2a (A, B, 
m, |i, a, 7C) *ft*L, *0)tt*36<, Xf^2 1 
8 -eu— b gjf L tcfi=7 > — ^ k [cH L l^^ <!: 9 
^^X h-f^o Z^lb^HLL>if^ N ^^^T>hfi^ 

^^U^iHT-r^o Xf >v^2 2 4t\ ^^^T>hfi 
k' =H 2b (A, B, m, ju, cr, 7T ) ZtiWt&o 

*BBE-rftfcftrcffl^6*iftztrc3Sft 0 x^^^2 2 

6lj\ ^^^r>hfi, K = H 3 (A, B, m, U , 

2 8T\ ^^^r>hf^, k- ^ 

fit* H^&cfctfh^te, sect^vh (fcffLse 

>^ A/\ ^ i/ zl Hfc-e fc « o 

[0 0 3 1 ] Xf>^23 0t\ "9— /<l±s £^(D7t<D 
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*nR£ffll^TH 2b (A, B, m, u, cr, 7T) £!t3t 

— £k' l:|LL^^^^fXht^)o -tlb 

ftfto z*i&*<*L<ftl^i«, ^'fTl/MiKE* 
ftftfr-ofcCQT^ +J— iMfrJu h=uu£«7-fft 0 Xt- 

7^2 3 2t\ It— K = H 3 (A, B, m, U , 

cr, 7T) d:Lti2'r>a>iK^4itl)c 
[0 0 3 2] Z©B#jft-C, /tO)H# 
f*Sl>£BELfcz£[cfty , ^^TV /\*[4 

[0 0 3 3] *[C % *^0^(7)m2j|»j^COL^Tg]3^ 

#«LtS«tSo croSffifiiradu S*#Peia)SiiEfi 
W (c UliE-r ft X t- y & l * - i: £ « «f ft o L 5 , 

»#p B ia)a«^prffit&So H3^#«g-rs<!:, x^ 

•V?3 0 2-3 1 0ld\ H2 0)XT-y ^2 0 2 -210 
fcfcfjS-fft, 7»=rv-fZ 1 2"£\ it— /Sf^ % /i = g y ■ 

(H 2 (A, B , 7l) ) mod piLt/<7^- 
$tf£!t*-ffto ZtU£ s g]2(cP^LTfj^L^X^^ 
72 0 4tlB«-eftSo *=rv-fZ 0 4[cHLTfj^iL 
fc«fc?l:: % S«[cfd\ Xf^3 1 2f* s 
X7- K©IHS£. Diffie-Hellmanffig y <t[c^LTII 
3S**Sff-rSztlcJ:y % d>ft<£*/<X9-K<DBI 
» *D i f f i e-He 1 1 manffi g y <h ft C |c ft ft 0 

[0 0 3 4] *[C % Xf^?3 1 4T\ It- /\*[*, X^ 1 
y?2 1 4(cHLTfj^!iLfc(D<t|B]4«[^s Diff ie-Hel I m 
anffi g x £tt a L s D i f f i e-He 1 1 man**r«ffl g x y £tt 
3Tf ft 0 XtV?3 1 6Tj\ +J— /^fi. K = H 3 (A, 
B, m, |i, cr, 7T) fcLT-fe^i/3>«K*tHtf 
fto X^^^3 1 8Tj\ /tfi, X^^^3 1 2X± 

[0 0 3 5] |i£5M5-*"ft£* Xf^32 

0T% ^fT>M3\ */lO>4t*<0 mod 

^X ft Q ZOll^O mod p-e&ft«^, £ ^ 
<fT> htt^P h=UU£»7-f ft„ Z(7)fi^0 mod 
p-CftLMi^, Xf^^3 2 2t\ ^^T^hl*. 
/iOffl^ffll^Ts fJ^iCOcfc^f^s Diff ie-Hel Imanffig y 

L s Diff ie-Hel lman**»« g x y £!t3J-f fto 
Xf>^3 2 4t\ ^^^7>Ht, K = H 3 (A, 
B, m, u, cr, 7T) fcLT-fe^e/3>«K*tHtf 

ft o 

[0 0 3 6] Z<7>B#jft-(?, ^7-<T> hfccfctflt- /^fi 



K^±jSLfcZ^[Cftft 0 ^^TV hfcJ;t/1t-/W 
]ELIV<X9- K^filf^LT^fct-filfi, f^#f^|w]i: 
-tZ^ V3 V^K^±^LTL>ftZ<*r[Cfty , Zft^ffll^ 
rS^ftjifl^pT^fcfto LfrU S*#0)-*J&*IE 
LlV^X9-K£m^LT^ftfr-o£:iil^ ^(7)^*# 
[*, ELL>tz^^3>^^4j$LTfcb-f\ ^*#P B 1(D 
Jiffi^Rl^tftfto 

[0 0 3 7] g|2fccfctfll 3 IZM LXmWLtcJn h =i 
;Ufe\ K;r£FJr*r LEttLTl^ftZfc 

£{5^LTl>fto Z(7)J:aft^P h=UU<7) 1 0<7)S^M 

ftMfljfitt* l*--/<Kffi«i«a>-fe*i u^-r sefticj: 

M:tt«, Z(7)d;9ft*S[c^-rft^^ffafc 
*rcKWTft*jiswa)t a 1 oa)Hffi«ijTM*, it- 
/^/U^- Fx > ft^byi-, i^^ft/^x 

9-K^'J^7>f7V^EltSo ^^X\ 
^'J 7r^T<tf^ s /U9- K0)Hftj: LTft3tpJ#£ft 

»A^bSiS-rftzt[i-e#fti^ cz-eKwrftH16«>J 

ftHft-efcfto fcf£L, flS(7)^7^7>hAfcJ;^ 
-/^BC^LT, V=g v s v=H 0 (A, B, 7t) V 
fcy, H 0 f4, I q | +s e c tfy h*U*Lftlt*ltf 

[3\ 7C ^^PoTl^ftfr^s v=H 0 (A, B, 7T) ^ft 
^-TftZ<t^-rr# s ^b(C s v^b^'J77^7V = g 
v * ft - 1 # ft o it-/^fi V L j^tt b ft l^fc 
v (zttf^ s vo)lt»W«-eftft) ^ft^1-ftz<b 
f*-e#fti> 0 ^WOcfloftlftffKCcfeft^p h=i;u^H 

4[C^"f 0 ^"f\ Xf^4 0 1t\ ^=^iT^V\X, 

±E0)j:arc/<x9-K'< | j7r>r7v*±«-rfto x 

^^^4 0 2-4 2 2f*. X^^^2 0 2-2 2 2 CHS 
LTtaaiLfccfc^lcllff^tLfto fcf£U Xf«v?40 
2-4 2 2TMi, /U^- K 71^/^X9— K^'J^T^ 
7Vtt#MSo Z0)B#jft-e, Xf'^4 2 2tfl)f 
X h fcftii^ ^^^T>hfi, It-zWiELL^ 
K^'J 77«<7V^^o TL^ ft Zt^SiELfc 

zticfty, ^^^r>hfi, i^iELLv^x 

9-K*ttoTl^ftZt*IEWrftZi:lcJ:o-C, i» 
i # ^' t t-/ DICKIE L X t b *5 ft Itilfift b ft L>o 
[0 0 3 8] Xf ^^42 4t, ^^^T>hfi, Z q 
fr6»*CtL-C7>4fAftttt»S;. I^^T^V 
(4, Xf^^42 6t\ a = g c ^ft^L, X^^^4 
28T\ e=H (A, B, m, , cr, a, V) £!tW 
"Tfto >^(C, Xf^?430t% ^7^^T>hf4, S = 
C-e v*tt*-rfto Xf^4 3 2t\ ^7^^T>h 
Its Sfccfct/a^+f— /^S«-ffto Sfcctt/a ^gjf 
■f ft «ts X5 1 ^^4 3 4T% It— /^fi, iB(DV(D^Pli 
e = H (A, B, m, U , a, a, V) £ft 
*-ffto Xf7^4 3 6t\ *-/<f±, g s V e ^tt^ 
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Xf 7^432t^7^7> hj6*&56«LfcaO>flti:- 
SrfS«^ +f—/\*[*, ^t^TTV h*J|jE&*a>i: L 

f^lf tlXf 7 ^4 3 8 fcJ;t/4 4 0 t\ K=H 

3 (A, B, m, u, a, a, V) £ LTiz ^ V a >H 

[0 0 3 9] HfiWlCfdu Xf7^4 3 6*C©fX h 

So ^4 3 6T?CQ a = g s V e <hl^-tJ— /^0)ft 

I^#Itii«l:> V = g v T?fo£f;:tf) s Xf'^436 
•COtHUi, a = g s (g v ) e =g s g ev =g 
s+ev =g c <h^So Xf^430^b, C = S + 

cGr {0,1}*, a 

fcf£U H 0 ' ld\ | q | + s e c tfy h*U*LSlt 
& b & I* fe S 7 > y A/ \ y v n. H ft -C : fo S o Xf'^ 

[ft2] 

fe = c 9 if 2a (A f B, m 5 ii, a, rr 5 V H ^ B ^ mod p, V) 
fcf£U 
Mt3] 

© 

c = «; uy n 2 a^i, 

[ft5] 

gH f 0 {A,B,c) moc [p 

£ft3IU tt*Lfcffitf. Xf^5 2 0t1f-A>b 

-■Cftl^**, U— aW7^7> hlCjEL<KBE£;h 
Tfcb?\ £^TV htt^P h=UU£«7-f£ 0 ft* 
ZtltcatfX^y^S 2 Otr+f— /^bfifi Ltca(D{$. 

a)-e&Si:*iJWfL, h^wxf 2 8(cii 

<?K k' =H 2b (A, B, m, jU, (7, a, k, c, 
V) £!t3t-f£o Xf^?530t, ^^rvhl*. 
■feyS>a >ftK = H 3 (A, B, m, jU , cr, c, V) 
^ft^-r^o Xf l V?5 3 2t% ^fr>M3: s k' 
$-9— /^^f-fSo Xf^^5 3 4t\ +f— /\*[*. H 
2b (A, B, m, jti, cr, a, k, c, V) £ft3t 
U ftJtLf-ffi^s Xf'V?532t^7'f7>h^b 

gffiLfck' (7)ffl<b^-^fes^^9^$^jif-rSo ^ 
--cfti***. S^rv hfi-9— /<rcBBE**iri36 



T> h^/U9- K7r£»oT^§»^lc<Z)<frft*"f § 
[0 0 4 0] «0^(7)ta 1 O0)||16filJ^Bl5[C^-r o 

z*it>. It- Ktf*Br*-rf, ttfrUlc, 

£^"fo *TVZf5 0 1- 5 14ft H4(CB|L-Cfia 
LfcX-ry 0 1-41 4 tm^'Cfo&o X^rvZfS 

1 ex\ it— /^[*, z q ^b7>^A^cJir/s a£ 
mi] 

fiSMfeWSISfP (XOR) £g|-fo Xf^520t% 
JU, a, k^^7-<7>^iaitl)o JW, 
a, k Xf ^?522t% ^7^7>h 

[£ s cr = jti x mod p^ft^-fSo Z<Dtff&X\ ^7 
^7>hfc<fct/1J-/mvf*itu ft*WfflCT*Bf* 
t6o Xf^?5 2 4t% ^^7>hf* s *a*tf* 

[«4] 

t><DXtb&tmKLs ^p h=i;ua)x^^^5 3 6(CJi 
^ s iz^V3>^K = H 3 (A, B, m, jW , (7, c, 

v) ttUM-«. 

[004 1 ] Mttrcfi, /ta)BBE 

$ffl[cf^ s T. EIGamal, "A Public Key Cryptosystem and 
a Signature Scheme Basedon Discrete Logarithms", 
IEEE Transactions on Information Theory, IT-31,4, 
pp. 469-472, 1985, fcffi«£;hTl^o -jttlc, > y-fe 
— vMf^ s XJU^fwUBf-^-lCcfc y E (M) = ( g r , y 
r M) tmmtZtl&o tztzLs r fiTV^Aftfit-efc 
Us yfi^BBft-efty, x*8MtLt, y = g x -e 

fe^)o Bb-^ (A, B) \ts D (A, B) =B/A X (bL 
rm-^tl^o ffl^ttA-rSi:, B/A x =y r M/g 

[ft6] 

£?(M) = (g r \H(y r )eM) 



10 



x^SffigtLt, y = g x T:fefto Bt# (A, B) 
[is C0)Sg2*jEI::J:;h,[i\ ^S0)J:9(ca-^$*LS o 
[*7] 

[ft8] 

e H{ y r ) e m = ff(y r ) e (y r ) © m = m 

K"Cftfto 

[0 0 4 2] ZZT% riBBEEUUtfvjUBt-^J £S 

%>tfs r fit, *^^Mft(C^>^A^fiO)^y[C % r 
= H' (M) s -fftfcti, a-^Sftftffia^^A/W 

i/zLt-TSo -©a^ a*##. ^ (a, b) 

[ft 9] 

a«f ^#,£n?feft#\ file) (a, b) f^sj^coer^ 
££«-fft#\ SBEififi, w*£fcBt^b£;iif::^ 

LfctfoT. £©»#fc*#m*&;h/C^ftfr*. 
BB^Hb * L o T I* ft Z t £ EE ifj t ft t, (7) -C ft 

fto 

[0 0 4 3] l5C^Lt^P h=UU£#88f 

ft<h, a*#rcr±B«i**i4j:3r=* xf;?5 1 6fc 

fto Bt#ft**lTl^ft> ^■iz-i?f* : 7>^Afic-C*fc 

[*vT*&So Bt^ffif*/^*-* klcttA**lT^fto 
Xff?5 2 4^ £ 7 *f 7 > h fd\ It- /^frbSflL 

*-/W3ELlv<X7- K^< 'J 7r^f7 V*Bf*L 
Tl^ftZi:j&<IiEE£;|ift 0 Xf'^5 2 8t% 9 ^ 4 7 
> hf*. cO)!t*ffi£ffl^T k' Xf*;?5 
3 2-Ck' £lt- /^S«-Tfto Xf^?5 3 4W 
-AdJzft^X haWCftftit** ^7-f7> h^IEL 
l>v £^LT^ftZ<t^IM£;hfto Wfflfc v tfftlt 

*u*\ ^^^Tvhfim-^^UffL-c, k^i-rsc-fftpg 

[0044] *jBwa>*fercaija)SiiiEfl-cf4, H2[c** 
ftfcUrc, fit (H 1 (A, B, x) ) r ^lEit-r^cfca 



fiUfeil lc b 4 ^ <t 9 W j£ *« ft ft „ 
[0 0 4 5] *%W<D3£W%\t* **W(cJ:ftffii:SiiE 
fcJ:t;«3E*^P h^U#££^ftftc<!:£EELfco 

<Dzt m.m L & b & l\ 

[0 0 4 6] (1) /U9-K5fttL^Ph^JH:« 

[0 0 4 7] (2) Diffie-Hellman^P h=UUA^^-C 
feftC<t^^^1-ft<t, *S69ia>7P h=UUfd\ 11*12 
;ruft^*#<t(7) rsSffiS^P h=iJUj <b|B]fI^[c^ 
■eftfto rssiss^p h=i;uj -cii, iESfe-S** 

[c s zo)=i*^i/a>*S*lc-rftfcfta)*^**W* 

£±j*L-ct,&?z£*<-e#ft*<, mz* m^zhtc^ 
-Kt««**L«a*#rciBi^t>-fr«ct36<wjB-eft 

£ff l\ i # i #*SBE L T t b a £ t" ft - <b 
^^MbLTl^fto ) 

[0 0 4 8] (1) o>«#fd\ ?p h=uu^M*ifiWb 

A^&fto 

[0 0 4 9] (2) 0«»f4, ctyStLL>o /U9-K 

b -f (c % SJBffiSa)« jE * *i ft S »# i> ft f£ it 

av^as-rftiafi, m&so)ii^p h=uu*as-Tft 

atfiESJ^ffi^&ftcfcaic-rftztA^-etftzt^^ 
1" 0 (z^fi s "multi-party s i mu I atab i I i ty" (ISft^ 

^Wm<DM.m$kfe-£fc> 1 ) s D. Beaver, "Secure Multipa 
rty Protocols and Zero-Knowledge Proof Systems To I 
erating a Faulty Minority", Journal of Crypto logy, 
4(2), pp. 75-122, 199K dffiK^Tl^fto ) 
[0 0 5 0] afl5M(cfi % t>jxt>lx<D=E^)\s\3:. "f^r 

(7)/\^ *>iM»j6<S£fc5 >^A-eft y s ^o)Bi»^ 

h**i4I!J) £^£LTl^ft 0 

[0 0 5 1 ] #3*lfc*l0)i/5i u— *0)-jttW&#iL* 

r*. mrc, siMcaflt-r«ia&-a*#iiiia)*^** 

ft«a* (»a)/\^^iH»Hi«i****-rftztrcj: 
y) ttUL, t*L6o>itait, «»i**ifta*#^a) 
rfxh/U9-Kj Bg^ic^^^at-rfttoD-eft 
ft 0 ztMDMLl^'A&s tltfs RS*hfe3**S/a 

> fcfc y lift n a) / ^ - KNiai ^ff 3 - # * ^ 

^pjf^-rrfeft<b-rft<b, Diff ie-Hel ImanRgHtfSltT L 
^9 (Sft^jfcfi, (^aODxtecfet/ylcWLT) X = 

g \ fccttfY^g^/^ix, y, zeGity, 
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[0052] ±Ka>BfflfcME[i, *&S«iJ^r*&o 

^RTffi"efcS 0 0>ia.fi, ±ieco^p h=uufcasi>-c, i> 
-< ic [* t- co -f^ r co/ > - £ tf&S £ * ii s t> it -efi 

60 U2C0^P h=UUC0X^^2 1 6 S 2 2 

2 S 2 2 4 s 2 3 0 s 2 2 6fed:tf2 3 2, [U3cZ)^P 
h^JKDX-r^ ^3 16j3J:tf3 2 4, [14C0^P h=l 
VUOX^y ^4 1 6, 4 2 2 S 4 3 8fcJ;tf4 40, ft 
bt/(cH5 0)^P S=UUC0X^y ^5 3 0fcJ;tf5 3 6 

I4 S ^p h=i;u^*MW(cS^"e&Sfctf)[cfi % /\^v 

?p h=i;ufifl^aM(cS^-efcS-tA<iiEifl*ii 
£ Q m4*lc % g]5cz)^p h=uua>x^^5 1 sfccfct/ 
5 2 4id\ ?p h=i^*MW(c$^-efcSfcaft[cfi % 

[»1 0] 



±E0)#in«i/<5>-*a)«fflrcj;y, :?Ph=uu 
« -e fe s z t tm m £ *i s o 

[0 0 5 3] 

/U9- KOWlc 

[H 1 ] fi£*(DDiff ie-Hel Iman^^lt^P h=UU£^"f 



OBtiRfltlSBESIffi*! [= <fc S S<S 7 □ h =i )l £ *f 0 "C fe 

<© m ^Mmummm i= «* a a« 7 □ h =uu £ a -e & 



[81] 



-H 



X = g x mod p 



V 



1G2 

104 
-106 



S = Y X mod p K 



114 



-112 



M 6r Z„ 



V = mod _p 



,10B 



.110 



\S = X y modpf 



116 
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[B2] 



202 



m = f ■ (Hi(A,B,Tc)) r modptf 



204 



a = {i~ mod p 



.220 



211 



h ! = H 2 b{A.B,m,ii,(T,'K) 



K = H 3 (A,±t,m : {t,a,n) 



-224 



-226 



B U— 



r206 



m 



205 



210 



fi = g y mod p p 



-i #-212 



£r - (m/(JJ 1 (A,B J *r)) r ) 1 ' mod p 



-214 



<21B 



216 



-228 



230 



232 
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[H3] 



^302 



= <f ■ (Hi{A, B. 7v)) s mod 



504 



m 



jfi ^ 0 mod p Y K 



-320 



ff = (^/(fr 2 (A,fl J ?r)) r )-iiiodp 



024 



r 3Q6 



?77. ^ 0 mod p ? 



-310 



U = Q y . (H 2 fA, B, 7r)) r mod pK 



r 312 



, ...... -nr^M 

■ - (m/(jJi(A,ij,7r))°) y modfff 
~ ' ,316 



r 318 



K — H s (A, B : m : fi : a- 7 ir) f 
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[H4] 



A *5-fT>h 



v = g v 



^401 



402 



m = g x • (Hi (A, V)) r mod p 



a = fi x mod p 



420 



-422 



424 



425 



e = if (A, m, /i, <7, a, V) ^ 



428 



S = C-ev r 



-450 



ir 438 

A" = H d [ A, B, m, o\ a, V r jr 



B -H— >N 



r 406 



rn / 0 mod p ? 



fi = g y mod p ^ 



^408 
410 
412 



cr = (m/(i?i(A 5 B, V)) r ) y mod pf 



-418 



fc = F aa (A,B l m )A »,^V)|'' 



416 



-432 



1 __, . _ 


«. IMP 




^436 





434 



44U 
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[H5] 



T/ _ r A li~ — II \ A fi .A 



ir 501 

V = g v V 



502 



x Ek Z q V 



m=g x - (Hi(A,B,V)) 3 modpf 



504 



' 506 



m ^ 0 mod p ? ' 



y £r ^ 



li — g y mod p 



508 

510 
512 



a = (m/(ffi(A, B, V)) 5 )* mod p 



■514 



-516 



* — m/ 522 

a = pr mod p r 



. 518 



524 



526 



• 528 



fe' = #2f>04, B, m, fi, a, a, fc, c, V) 



,536 



(71) BEX 596077259 

600 Mountain Avenue, 
Murray Hill, New Je 
r s e y 07974-0636U. S. A. 

(72) 5801# xy?$ yn^-tz 

T>'J*^«I1, 07922, -^-v-v-v 

-#L /wx y — X □— 

K 140 



7>'J***H. 10952, 
"7>v- N JU- h306, 244 

7* 'Jrt^ffell, 07040 -^-v-v-v 
-#L J^^UO'VK, *-JUh> =i- 
h 11 

(72)^0jm "9" /^;u 

7* 'J***H, 07045 -^-v-v-v 
-Jl ^Vh^Jk 5 5 — U-> 34 
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